CareFirst, Inc.
ent_73abc7125bb3aca4ee7b6a98
Disclosures
1
State AG · 1 jurisdiction
Multi-filing incidents
—
no multi-filing incident in sample
Max affected reported
69
as filed · State AG MA
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- CareFirst, Inc.
- Normalized
- carefirst— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (1)newest first
Subsidiary disclosures (6)filed by group companies
◈ These filings were made by or about subsidiaries of CareFirst, Inc. — not by CareFirst, Inc. itself. Corporate relationships are mapped from GLEIF relationship records and SEC Exhibit 21 filings.
- Montana State AGvia Trusted Health Plans, Inc.2021-04-08
Trusted Health Plans, Inc. notified Montana and other states of a cybersecurity incident discovered on January 28, 2021. A foreign cybercriminal group likely stole personal information, including names, addresses, and SSNs/TINs, from Medicare Advantage and Exchange plan records. The company engaged the FBI and CrowdStrike, isolated systems, and reset passwords. Affected individuals were offered two years of Experian IdentityWorks.
- Indiana State AGvia Trusted Health Plans, Inc.2021-04-07
Trusted Health Plans, Inc reported a data breach to the Indiana Attorney General. The breach occurred on 2021-01-25 and was reported on 2021-04-07. 17 Indiana residents were affected. 211,000 individuals affected in total.
- Massachusetts State AGvia Trusted Health Plans, Inc.2021-04-05
Trusted Health Plans, Inc. reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2021-04-05. 28 Massachusetts residents were affected. The report records the breach type as electronic.
- New Hampshire State AGvia Trusted Health Plans, Inc.2021-04-05
Trusted Health Plans, Inc. notified the NH Attorney General of a security event discovered on Jan 28, 2021, involving unauthorized access to personal information of 5 NH residents (providers). Data potentially exfiltrated included names, addresses, SSNs, and TINs. The company engaged CrowdStrike and FBI, isolated systems, reset passwords, and offered 2 years of Experian IdentityWorks.
- Maine State AGvia Trusted Health Plans, Inc.2021-04-05
Trusted Health Plans, Inc., a subsidiary of CareFirst, Inc., reported a data breach that was discovered on January 28, 2021. The breach, which occurred on January 25, 2021, was an external system breach (hacking) that affected one Maine resident. The compromised information included names or other personal identifiers in combination with Social Security numbers. The company provided two years of identity theft protection services through Experian IdentityWorks to the affected individual.
- DISTRICT OF COLUMBIAHHS OCRvia Trusted Health Plans, Inc.2021-03-26
Trusted Health Plans, Inc. reported to HHS on 2021-03-26 a Hacking/IT Incident affecting 200,665 individuals. Breached information located on Network Server. The incident involved a ransomware attack exposing ePHI including names, addresses, SSNs, DOBs, and treatment data.